||11-05-2012 03:25 PM
search query product name
First i want to match the search keyword with the product name in product table.
If the match is found then i want to fetch all the product details from product table for that product.
so i would like to know whether my code is fine or not.
can this be shortened
$searchword = $_REQUEST['searchword'];
$qry = "select product_name from product_table where product_name LIKE '%$searchword%'";
$result = mysql_query($qry);
if(mysql_num_rows($result) > 0)
$searchqry = "select * from product_table where product_name LIKE '%$searchword%'";
$searchresult = mysql_query($searchqry);
while($searchrow = mysql_fetch_array($searchresult))
||11-05-2012 05:22 PM
use addslashes() when putting user input into an SQL query or else the presence of an apostrophe in it can cause problems
$qry = "select product_name from product_table where product_name LIKE '%".addslashes($searchword)."%'";
|All times are GMT +1. The time now is 02:43 AM.
Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.